CVE-2025-34489 Details
Description
GFI MailEssentials prior to version 21.8 is vulnerable to a local privilege escalation issue. A local attacker can escalate to NT Authority/SYSTEM by sending a crafted serialized payload to a .NET Remoting Service.
A local privilege escalation vulnerability has been identified in GFI MailEssentials versions prior to 21.8. This issue allows a local attacker to escalate privileges to NT Authority/SYSTEM by sending a crafted serialized payload to a .NET Remoting Service. The vulnerability arises from the use of the 'BinaryFormatter' for deserialization, which can be exploited to execute arbitrary code with elevated privileges.
Users are advised to upgrade to GFI MailEssentials version 21.8 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 28, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-502 | Deserialization of Untrusted Data | [email protected] |
| CWE-502 | Deserialization of Untrusted Data | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| gfi mailessentials | < 21.8 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 4, 2025 | CVE Modified | [email protected] |
| May 10, 2025 | Initial Analysis | [email protected] |
| Apr 28, 2025 | New CVE Received | [email protected] |